Mixed Deck — All CSC Topics Flashcards
100 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 20 Mixed Deck — All CSC Topics flashcards as text
Which tabletop exercise element is most valuable for identifying gaps in an emergency response plan?
Answer: Realistic scenario injects that reveal untested decision points
Scenario injects introduce unexpected developments that expose gaps in planning and decision-making processes.
What is the primary goal of security risk management?
Answer: To manage and reduce risks to acceptable levels
The primary goal of security risk management is not to eliminate all threats, which is often impossible and cost-prohibitive. Instead, it aims to identify, assess, and implement controls to reduce risks to a level that the organization deems acceptable. This strategic approach ensures resources are allocated effectively to protect critical assets without hindering business functions.
A team conflict arises because two analysts disagree on the severity rating of a vulnerability. The MOST appropriate resolution approach is to:
Answer: Reference the agreed-upon scoring framework (e.g., CVSS) and apply it objectively to the vulnerability
Using an established scoring framework (such as CVSS) removes personal bias and provides an objective, defensible basis for severity ratings.
What is the role of encryption in data security?
Answer: Protecting data confidentiality during storage and transmission
Encryption protects data confidentiality by making information unreadable without proper decryption keys, whether data is stored (at rest) or being transmitted (in transit).
What is the most important principle in professional Court Security Specialist practice?
Answer: Maintaining competence through continuous learning and adherence to standards
Maintaining competence through continuous learning and adherence to professional standards ensures quality service delivery and public protection in Court Security Specialist practice.
A client requests a video analytics system that automatically alerts on abandoned objects. What is the MOST significant challenge of this technology?
Answer: False positive rates in busy environments
Abandoned object detection frequently generates false alarms in high-traffic areas where objects are temporarily set down and people move around them.
A client asks a security consultant to help document the step-by-step procedures for recovering a specific IT application after a failure. This document is called a:
Answer: System Recovery Procedure (SRP) or IT Disaster Recovery Plan
A System Recovery Procedure or IT Disaster Recovery Plan contains the specific technical steps required to restore a particular system or application after failure.
Which compliance framework is specifically designed for cloud service providers handling US federal government data at the FedRAMP Moderate baseline?
Answer: FedRAMP Moderate ATO
FedRAMP Moderate Authorization to Operate (ATO) is the specific authorization cloud providers must obtain to host federal agency data classified at the moderate impact level.
What is 'video latency' in a surveillance system and why does it matter for live monitoring?
Answer: The delay between a real-world event and its display on the operator's monitor
High latency means operators see events seconds after they occur, which can impair real-time response to security incidents requiring immediate action.
During a security assessment interview, silence from the interviewee after a question is BEST handled by:
Answer: Allowing the silence to continue briefly, as it often prompts the interviewee to provide more information
Comfortable silence is a powerful interview technique—interviewees often fill silence with additional, sometimes critical, information.
Which element is LEAST relevant when evaluating whether a security officer's use of force was objectively reasonable?
Answer: The officer's subjective fear level
Objective reasonableness is evaluated from the perspective of a reasonable officer, not the subjective mental state of the individual officer.
A security manager is developing a training program. Which training method is MOST effective for teaching officers how to respond to a medical emergency?
Answer: Hands-on scenario-based drills simulating actual medical emergencies
Scenario-based hands-on drills build muscle memory and decision-making skills that are retained far better than passive instructional methods for emergency situations.
Which perimeter security measure BEST addresses the threat of drone-based surveillance or payload delivery at a secure facility?
Answer: Counter-UAS (C-UAS) detection and mitigation systems
Counter-UAS systems use radar, RF detection, acoustic sensors, and mitigation tools (jamming, nets, directed energy) to detect and neutralize drone threats.
How should a Court Security Specialist professional handle situations beyond their expertise?
Answer: Refer to a qualified specialist and communicate transparently with the client
Referring to qualified specialists when facing situations beyond personal expertise protects clients and upholds professional integrity.
A CSC is evaluating a cloud provider's shared responsibility model for risk allocation. Who is primarily responsible for data classification in an IaaS environment?
Answer: The customer/tenant organization
In IaaS, the customer retains full responsibility for data classification, access control, and application security above the infrastructure layer.
Which of the following best defines 'resilience' in the context of organizational security and continuity?
Answer: The capacity of an organization to absorb disruption and adapt to maintain acceptable operations
Organizational resilience is the adaptive capacity to absorb stress, recover functionality, and adapt to new circumstances while maintaining acceptable operations.
What is the first step before implementing any treatment procedure?
Answer: Verify patient identity and obtain informed consent
Verifying patient identity and obtaining informed consent is always the first step before any treatment, ensuring patient safety and legal compliance.
What is a vulnerability assessment?
Answer: A review of system weaknesses and risks
A vulnerability assessment is a systematic process of identifying and quantifying security weaknesses (vulnerabilities) in a system, network, or application. It aims to determine which assets are susceptible to attack and how severe these weaknesses are. This provides a basis for prioritizing and addressing potential security gaps before they can be exploited by threats.
Which risk assessment framework is commonly used by US federal agencies and contractors and is published by NIST?
Answer: RMF (SP 800-37)
NIST SP 800-37 defines the Risk Management Framework (RMF), which is mandatory for US federal information systems.
A facility security director wants to test the effectiveness of the physical security program without alerting staff. This type of assessment is called a:
Answer: Red team or penetration test
A red team exercise or physical penetration test involves unannounced, real-world attempts to bypass security controls to identify gaps that staff and technology might otherwise miss.